CVE-2026-85004
Received Received - Intake

Privilege Escalation in Popup Maker WordPress Plugin

Vulnerability report for CVE-2026-85004, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: WPScan

Description

The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
popup_maker popup_maker to 1.4.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Popup Maker WordPress plugin (versions 1.4.5 and below) allows authenticated users with minimal privileges, such as Subscribers, to overwrite a site-wide plugin option that should only be modifiable by administrators. The issue occurs because the plugin performs a nonce check but fails to verify user capabilities before allowing the modification.

Detection Guidance

Check if the Popup Maker plugin version 1.4.5 or below is installed. Look for unauthorized modifications to site-wide plugin options, especially those related to service accounts or API configurations. Review user activity logs for actions tied to the sgpm_connect endpoint by non-administrative users.

Impact Analysis

An attacker with Subscriber-level access could change critical site-wide settings, such as linked service accounts and API configurations. This could lead to unauthorized access, data breaches, or disruption of plugin functionality. The impact includes potential compromise of site integrity and confidentiality.

Compliance Impact

This vulnerability could lead to unauthorized modifications of plugin settings, potentially exposing sensitive data or violating access control requirements. For GDPR, it may impact data protection measures, while for HIPAA, it could compromise protected health information integrity. Compliance may be affected due to unauthorized access or data exposure risks.

Mitigation Strategies

Update the Popup Maker plugin to the latest version. Remove or restrict Subscriber-level access if not required. Audit and revert any unauthorized changes to plugin settings. Monitor for suspicious activity related to the sgpm_connect action.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85004. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart